logo

The ‘Madi’ infostealers – a detailed analysis - Securelist

ID: 89dc065d-7ea2-4fb4-b3c7-132ff14a0d1d

STIX ID: report--89dc065d-7ea2-4fb4-b3c7-132ff14a0d1d

Threat Score

70/100

Uploaded: 2026-08-19

Published Date: 2014-07-15

Last Modified Date: 2014-07-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a detailed reverse-engineering analysis of the Madi infostealer campaign: how downloaders install the infostealer, the Delphi-based malware structure (52 timers), keylogger and screen/audio capture capabilities, file-collection and exfiltration workflows (Base64, Sendfilejj.html/sik.php), C2 check-in and command retrieval (dastor/dast.xls, ReReReRe.htm/SeSeSeSe.htm), and numerous filenames/markers used for control and exfiltration (e.g., nam.dll, poki65.pik, *.BMH, *.KILOP, tamamshodfile). Despite sloppy coding, the campaign was effective with ~800 victims and multiple active data-stealing primitives.